The FBI, in collaboration with Google and Black Lotus Labs, has dismantled Outsider Enterprise, a China-based phishing-as-a-service operation responsible for stealing 3.8 million credit card records.
Key Points
- The operation utilized AI and distributed phishing kits to impersonate trusted brands via SMS messages sent through AT&T, T-Mobile, and Verizon.
- Google identified over 9,000 fake websites and more than one million fraudulent URLs linked to the network since 2023.
- Authorities seized administration servers, a Shopify storefront, and $100,000 in cryptocurrency as part of the broader Operation Riptide.
- The FBI took control of a Telegram bot used by the threat actors to manage customers and distribute phishing tools.
- Google has filed a civil lawsuit to disrupt the infrastructure and is advocating for bipartisan legislation like the Stop SCAMS Act.